customer-research
Pass
Audited by Gen Agent Trust Hub on Jun 20, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill consists of markdown instructions and configuration files designed to guide the AI agent through research workflows. No executable scripts, network exfiltration commands, or obfuscated payloads are present.
- [PROMPT_INJECTION]: The skill's primary function is to analyze untrusted external data (e.g., transcripts, surveys, Reddit posts, and review sites), which inherently presents a surface for indirect prompt injection.
- Ingestion points: Data entering the context via transcripts, survey results, support tickets, and various online community platforms (Reddit, G2, Hacker News) as described in references/guidelines.md and references/source-guides.md.
- Boundary markers: None explicitly used to delimit processed data from agent instructions.
- Capability inventory: Uses file-read access for research assets and web searching/browsing for gathering online intelligence.
- Sanitization: No automated sanitization is applied; however, the skill mandates manual 'confidence scoring' and 'sample bias checks' in references/guidelines.md to mitigate data quality and manipulation risks.
Audit Metadata